security research
iltosec
ILTOSEC
writeups & research

Blog

RSS
14 posts
/
categories
tags
CVE·File Upload Bypass · CVE·File Upload Bypass
CVE-2024-11404: Medium Severity File Upload Vulnerabilities in django-filer 3.2.3
Unrestricted Upload of File with Dangerous Type, Improper Input Validation, Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in django CMS Association django Filer allows Input Data Manipulation, Stored XSS.This issue affects django Filer: from 3 before 3.3.
2024-11-20
4836 2 5 min read
Ransomware · Ransomware
What is Ransomware, How Does It Work, How Can We Be Protected?
Discover what ransomware is, how it works, its history, famous ransomware attacks, and effective strategies to protect yourself and your business from this dangerous malware.
2024-11-19
1087 3 7 min read
Xss·CVE · CMS·CVE
Django CMS 4.1.3 Stored XSS Vulnerability: Exploiting the Page Title Field
CVE-2024-11319 Discover the stored XSS vulnerability in Django CMS 4.1.3 that affects the Page Title field. Learn about the security risks, exploitation methods, and remediation strategies to protect your site from potential attacks. CVE-2024-11319 stored XSS vulnerability, Django CMS 4.1.3, CVE-2024-11319, JavaScript injection, Django CMS 4.1.3 CVE-2024-11319, admin panel security, Cross-Site Scripting, security patch, CVE, content security policy, input sanitization
2024-11-11
4365 15 3 min read
Rce · Rce
Remote Code Execution by Bypassing Cloudflare: CVE-2022–29464 Analysis
Explore the detection and exploitation of CVE-2022-29464, a critical vulnerability in WSO2 products that allows remote code execution. Learn how to bypass Cloudflare's security and achieve shell access with a custom web shell. This article provides a detailed step-by-step guide, highlighting important lessons in web application security and the need for constant testing and updating of defense mechanisms.
2024-11-11
1867 7 8 min read
← prev 1 2